02-17-2023 02:00 PM
What is everyone doing to get SGT tags applied to clients authenticating 8021x via ISE? We recently migrated to WLC9800's, I have gone through the TrustSec config section of the WLC. My WLC's are aware of the SGT's mappings from ISE, but none of my clients are getting assigned any tag. FYI, any client authenticating NOT through the WLC, SGT's are working. Anyway, I worked through the limited documentation there is for using the inline tagging off the flex profile, but that hasn't solved any issues. Just curious for now, how others are getting their wireless clients tagged. My environment is WLC9800 with 1852 AP's in flex mode.
02-17-2023 02:08 PM
how is your config looks like:
check below guide :
02-17-2023 02:58 PM
Thanks. I followed this document when setting up the WLC. So, our implementation follows this almost exactly. However, none of our clients connecting through the WLC are getting a security group (SGT) assigned to them from ISE. FlexConnect works as expected. This is the document that I found with re to inline tagging. However, still not providing me with a solution nor what I expect to see as far as ISE authentication. Non wireless clients are assigned a security group tag to align with our TrustSec implementation.
02-23-2023 09:29 AM
Could this be my issue? The switch that my vWLC is connected to runs NX-OS, which cannot be enabled for CTS/SXP. So when it says to peer with the upstream switch, assuming that has to be aware of the SGT's on your network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide